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J>5 (57) Abstract: A method for detecting malicious code in a stream of data traffic input (400) to a gateway in a data network by 
O monitoring for suspicious data in the stream of data traffic (407). Upon detecting the suspicious data, an attempt is made to disas- 
O semble the suspicious data (403) and a threat weight is assigned for each instruction. The attempt to disassemble is initialed at initial 
instructions each with a different offset within the suspicious portion of data. The threat weights are accumulated respectively for 



Q each branch option in the disassembled code (403), producing respectively an accumulated threat weight for each branch option. 
^ When the accumulated threat weight exceeds a previously defined threshold level, an alert is generated and/or traffic is blocked from 
the source of the malicious code. 
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